¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180920

°ä²¼¹¦·ò 2018-09-20

¡¾·ÖÎö»ã±¨¡¿Å·ÖÞÐ̾¯×éÖ¯°ä²¼2018Ä껥ÁªÍøÓÐ×éÖ¯·¸×ïÍþвÆÀ¹À»ã±¨


Å·ÖÞÐ̾¯×éÖ¯Â½ÐøµÚÎåÄê°ä²¼»¥ÁªÍøÓÐ×éÖ¯·¸×ïÍþвÆÀ¹À»ã±¨£¨IOCTA2018°æ£©£¬»ã±¨ÖÐÈ«Ãæ¸ÅÊöÁ˵±Ç°ÒÔ¼°½«À´µÄ·¸×ïÍþвºÍÇ÷Ïò¡£ÆäÖØÒª·¢ÏÖÔ̺¬£ºÀÕË÷Èí¼þÈÔά³ÖÖ÷µ¼Ö°Î»£»·¸×ï·Ö×Ó³ÖÐøÀûÓÃDDoS¹¥»÷Õë¶Ô¸öÈËÆóÒµºÍ¹«¹²ÐÐÒµ£»¶ùͯÐÔ°þÏ÷×ÊÁϵÄÊýÁ¿³ÖÐøÔö³¤£»ÎÞ¿¨Ö§¸¶Ú²Æ­³ÉΪÖ÷Á÷£¬µ«skimmerÈÔÔÚ³ÖÐø·¢Õ¹£»Õë¶Ô¼ÓÃÜÇ®±Ò³ÖÓÐÕߺÍÂòÂôËùµÄ·¸×ï»î¶¯ÉÏÉý£»¶ñÒâÍÚ¿ó³ÉΪ³±Ë®£»Éç½»¹¤³ÌÒÀÈ»ÊdzÁÒªµÄ¹¥»÷ÏòÁ¿£»ÖØÒªµÄ°µÍøÊг¡±»¹Ø¹Ø£¬µ«ÒµÎñ»¹ÔÚ½øÐС£


https://www.europol.europa.eu/internet-organised-crime-threat-assessment-2018


¡¾·ÖÎö»ã±¨¡¿Akamai°ä²¼2018Ä껥ÁªÍø°²È«Çé¿ö»ã±¨£¬³Áµã¹Ø×¢Í´´¦Ìî³ä¹¥»÷


Akamai°ä²¼2018Ä껥ÁªÍø°²È«Çé¿ö»ã±¨£¬³Áµã¹Ø×¢½ðÈÚÐÐÒµÃæ¶ÔµÄй¥»÷Ç÷Ïò - Í´´¦Ìî³ä¹¥»÷¡£2018Äê5ÔÂÖÁ6ÔÂÆÚ¼äAkamaiÔÚÆäÖÇÄÜÆ½Ì¨ÉϹ²¼ì²âµ½³¬¹ý83ÒڴζñÒâµÇ¼³¢ÊÔ¡£»ã±¨·ÖÎöÁ˽©Ê¬ÍøÂçµÄ×îÐÂÕ½ÊõºÍÇ÷Ïò£¬Ô̺¬Ö¸±êÐÐÒµºÍ¹ú¶È£¬²¢Éî¿Ì×êÑÐÁËÒ»¸öÕë¶ÔÁ½¸ö½ðÈÚ»ú¹¹µÄ¶à½©Ê¬ÍøÂç¡¢³¤¹¦·òµÄÍ´´¦Ìî³ä¹¥»÷¡£»ã±¨Öл¹·ÖÎöÁËÍ´´¦Ìî³ä¹¥»÷Ôö³¤µÄÔ­ÒòÒÔ¼°×éÖ¯¸Ä½øÆä·À»¤´ëÊ©µÄ±ØÒªÐÔ¡£


https://www.akamai.com/us/en/about/our-thinking/state-of-the-internet-report/global-state-of-the-internet-security-ddos-attack-reports.jsp


¡¾¹¥»÷ÊÂÎñ¡¿ÃÀ¹ú¹úÎñÔºµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬Ô¼1%Ô±¹¤µÄÐÅϢй¶


ÃÀ¹ú¹úÎñÔºµÄµç×ÓÓʼþϵͳÔâµ½ºÚ¿Í¹¥»÷£¬ÉÙÊýÔ±¹¤£¨²»µ½1%£©µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜй¶¡£Æ¾¾Ý¹úÎñÔº°ä²¼µÄ²¼¸æ£¬¸Ãµç×ÓÓʼþϵͳ³¤¶Ì»úÃÜÐÔµç×ÓÓʼþϵͳ£¬Æä±»ÃèÊöΪÃô¸Ðµ«²»Éæ¼°»úÃÜ¡£¹úÎñÔº½²»°ÈËNicole Thompson°µÊ¾ÕâÒ»ÊÂÎñ»¹ÔÚµ÷²éÖ®ÖУ¬¹úÎñÔºÔÚÓëºÏ×÷ͬ°éºÍ˽Ӫ²¿ÃÅ·þÎñÉ̹²Í¬½øÐÐÈ«ÃæµÄÆÀ¹À¡£


https://www.politico.com/story/2018/09/17/state-department-email-personal-information-792665


¡¾¹¥»÷ÊÂÎñ¡¿·ÆÂɱö¹ã²¥¹«Ë¾ABS-CBNÔâºÚ¿Í¹¥»÷£¬²¿Ãſͻ§µÄ²ÆÕþÊý¾ÝÒɱ»ÇÔ


·ÆÂɱö¹ã²¥¹«Ë¾ABS-CBNµÄÔÚÏßÉ̵êϰȾMagecart¶ñÒâ¾ç±¾£¬²¿Ãſͻ§µÄÖ§¸¶ÐÅÏ¢ÒÉй¶¡£Æ¾¾ÝºÉÀ¼°²È«×êÑÐÈËÔ±Willem GrootµÄ˵·¨£¬¸Ã¶ñÒâ¾ç±¾×Ô2018Äê8ÔÂÒÔÀ´Ò»Ïò»îÔ¾¡£ABS-CBNÊÇ·ÆÂɱö×î´óµÄÓÐÏßµçÊÓ·þÎñÉÌ¡£ÕâЩ±»À¹½ØµÄÓû§²ÆÕþÊý¾Ý±»·¢Ë͵½×¢²áְλÓÚ¶íÂÞ˹ÒÁ¶û¿â´Ä¿ËµÄ·þÎñÆ÷¡£Ä¿Ç°»¹²»Ã÷ÏÔÓм¸¶à¿Í»§Êܵ½Ó°Ïì¡£


https://www.zdnet.com/article/broadcasting-giant-abs-cbn-customer-data-stolen-sent-to-russian-servers/


¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±Åû¶Î÷ÊýMy Cloud NASÉ豸ÖеÄÒ»¸öÉÐ佨¸´µÄ°²È«·ì϶


SecurifyµÄ×êÑÐÈËÔ±Åû¶Î÷²¿Êý¾ÝµÄMy Cloud NASÉ豸ÖеÄÒ»¸öÉÐ佨¸´µÄ°²È«·ì϶¡£¸Ã·ì϶£¨CVE-2018-17153£©¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÌáȨÖÁÖÎÀíԱȨÏÞ£¬²¢»ñµÃ¶ÔÊÜÓ°ÏìNASÉ豸µÄÆëÈ«½ÚÔ죬ÒÔ¼°Äܹ»²é¿´¡¢¸´Ô졢ɾ³ýºÍ¸²¸ÇÉ豸ÉϵÄÈκÎÎļþ¡£×êÑÐÈËÔ±»¹°ä²¼ÁËÓйØPoC¡£¸Ã·ìÏ¶ÔøÓÚ2017Äê4Ô»㱨¸øÎ÷²¿Êý¾Ý£¬µ«¸Ã¹«Ë¾ÖÁ½ñûÓнøÐÐÈκλظ´ºÍ½¨¸´¡£


https://thehackernews.com/2018/09/wd-my-cloud-nas-hacking.html


¡¾·ì϶²¹¶¡¡¿Ë¼¿Æ°ä²¼WebexÍøÂç¼Ôì²¥·ÅÆ÷µÄ°²È«¸üУ¬½¨¸´¶à¸ö·ì϶


˼¿Æ½¨¸´ÁËWebexÍøÂç¼Ôì²¥·ÅÆ÷ÖеĶà¸ö°²È«·ì϶¡£ÕâЩ·ì϶ÊÇÓÉÓÚWebex¼ÔìÎļþµÄ²»ÕýÈ·ÑéÖ¤µ¼ÖµÄ£¬¹¥»÷Õß¿ÉÄÜͨ¹ý´¹µöÁ´½Ó»ò´¹µöÓʼþÓÕʹÓû§´ò¿ª¶ñÒâµÄARFÎļþ´¥·¢ÕâЩ·ì϶£¬µ¼ÖÂËÁÒâ´úÂëÖ´ÐС£¸ÃÈí¼þµÄWindows¡¢OS XºÍLinux°æ±¾¶¼Êܵ½Ó°Ï죬½¨ÒéÓû§¾¡¿ì½øÐиüС£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180919-webex



¡¾GA»Æ½ð¼×¼¯ÍÅADLabÕû¶Ù°ä²¼¡¿